Privacy Policy
1. Who we are
[Legal Entity Name] (“TrustBiz”, “we”, “us”) operates TrustBiz, a business-verification and certification service for India. For the personal data we handle to verify a business, we act as the Data Fiduciary under India's Digital Personal Data Protection Act, 2023 (DPDP).
This policy explains what we collect, why, how we protect it, who we share it with, and the rights you have.
2. Information we collect
Business & identity details you provide to be verified: business/trade name, owner/proprietor name, GSTIN, Udyam (MSME) number, PAN, a bank account number + IFSC and/or a UPI ID, and — where you choose identity confirmation — an Aadhaar number for a one-time OTP check.
Documents you upload (e.g. GST/Udyam/PAN/incorporation/Aadhaar certificates) so we can read and match the details.
Account & contact details: email, mobile number, and optional business links (website, social handles).
Consent records: a timestamped record that you authorised each verification.
Minimal technical data needed to run the service securely (e.g. rate-limiting signals). We do not use advertising trackers.
3. How we use your information
To verify your business against official and banking records (GST, PAN, MCA, Udyam, bank/UPI penny-drop, Aadhaar OTP), match the returned name to your business, and issue and maintain your certificate.
To re-verify periodically and update, suspend, or revoke a certificate if the underlying status changes.
To operate the public verify page, registry, seal, renewals, and to provide support.
We do not sell your personal data, and we do not use it for advertising.
4. Consent
We run a verification only after you give explicit consent, which we log. You may withdraw consent for future processing at any time; withdrawal does not affect processing already carried out, and may mean we can no longer maintain your certificate.
5. How we protect sensitive identifiers
Sensitive identifiers (PAN, bank account, GSTIN, Udyam, UPI, Aadhaar) are encrypted at rest (AES-256-GCM) and are never displayed in full on any public page.
For lookups we store one-way fingerprints, not the raw value where a fingerprint suffices — for example a UPI ID is matched by fingerprint only and is never stored, returned, or logged in the clear.
An Aadhaar number is used only for the one-time OTP check and is not stored.
Public surfaces (verify page, registry, seal, buyer checks) show only masked values and a red/amber/green status — never a full bank account or identifier. The embeddable seal carries a signed, tamper-evident token.
6. Who we share it with (processors)
We share the minimum necessary with data processors acting on our instructions: KYB/verification providers (for GST/PAN/bank/UPI/Udyam checks), our AI document-reading provider (to extract fields from documents you upload), a payment gateway (if you pay), SMS/email providers (OTP and notifications), and our cloud hosting/storage. Each is bound to use the data only to provide its service.
We may disclose information where required by law or to protect against fraud or misuse.
7. Your rights under DPDP
You may request access to and a copy (export) of your data, correction of inaccurate data, and erasure of your data. Signed-in users can export or request deletion from within the app; certificates that were publicly issued retain only a minimal tombstone so the public registry stays accurate.
You may also withdraw consent and raise a grievance with our Grievance Officer (below). If unresolved, you may approach the Data Protection Board of India.
8. Retention
We keep your data for as long as your certificate is active and for a defined retention period thereafter to meet legal, audit, and registry-integrity needs, after which it is deleted or irreversibly anonymised. [Confirm retention periods with counsel.]
9. Buyers who check a business
When someone checks a business (on the web or WhatsApp), we record only anonymous, aggregate counts (e.g. a check happened, or a UPI didn't match). We do not store the checker's identity, phone number, IP, or message content.
10. Security, children & changes
We apply administrative and technical safeguards appropriate to the sensitivity of the data. No system is perfectly secure; if a breach affects you, we will notify you and the authorities as required by law.
TrustBiz is for businesses and is not directed to children; we do not knowingly process the data of minors.
We may update this policy; we will post the new version here with a revised “Last updated” date.
11. Contact & Grievance Officer
Questions or requests: [Grievance Officer name] · [privacy@yourdomain] · [postal address].